Jetpack Boost
cpe:2.3:a:automattic:jetpack_boost:*:*:*:*:wordpress:*:*
- < 3.4.7
A server-side request forgery (SSRF) vulnerability has been identified in the Jetpack Boost WordPress plugin, affecting versions prior to 3.4.7. This vulnerability allows administrators to make GET requests to arbitrary URLs, potentially leading to unauthorized access or manipulation of data.
Exploitation of this vulnerability could allow an authenticated administrator to perform SSRF attacks, which could be used to access internal services or resources that are not normally exposed to the public.
Users can update to Jetpack Boost version 3.4.7 or later to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.